Recommendations
Precise and clear definition of the categories of personal data that are being collected and shared is needed.
As for the cases when the data should be given to the National Insurance Bureau for analyses, the Consent of the data subject should be stipulated by law.
Period of keeping personal data in the Information register at the National Insurance Bureau is defined “at least for 7 years”. This formulation is not in compliance with the LPDP because the keeping period should be concrete and precise.
Law on Compulsory Traffic Insurance also needs additional provision for the technical and organizational measures not only for the internal procedures of the insurance companies but as well for the conclusion of agreements with the data Users and sharing data with other subjects (MOI, MLSP etc).